[MFA Modernization Pilot] Add MFA Sign-in Method: Hardware Security Key (FIDO2)

⚠️ WARNING: This article is intended for participants in the MFA Modernization Pilot only. If you are not a pilot participant, the information in this article may not apply to you. Contact the IT Service Desk if you have questions about your current sign-in experience.

This article walks you through adding a hardware security key as a passkey for your University of Maine System (UMS) account. A passkey stored on a security key is a physical device you plug in and touch to verify your identity when signing in.

ℹ️ INFO: We recommend setting up at least two sign-in methods on two different devices, such as this security key plus the Microsoft Authenticator app on your phone, so you are not locked out if you lose access to one device.

Instructions

How would you like to complete this setup?

Self-guided

Go to aka.ms/mfasetup and follow the on-screen prompts.

📖

Written instructions

Jump to step-by-step instructions

▶️

Guided video

Jump to the video walkthrough

🛠️

Common problems

Jump to troubleshooting


ICON KEY: 💻 = do this on your computer    🔑️ = do this on your security key

Before you begin

  • 💻 A computer with a web browser
  • 🔑️ A hardware security key (FIDO2), such as a YubiKey, with a PIN already set up

If you have not yet created a PIN for your security key, see Understanding YubiKey PINs (External Link) before continuing.

ℹ️ INFO: These instructions use a Windows 11 computer. If you are using a different operating system, such as macOS, Linux, or Windows 10, your options may look slightly different.

Registering your security key

  1. 💻 On your computer, open a web browser and go to aka.ms/mysecurityinfo.
  2. 💻 Under "Security info," click Add sign-in method.
  3. 💻 In the "Add a sign-in method" box, select Passkey from the list.
  4. 💻 In the "Sign in faster with your face, fingerprint, or PIN" box, click Next.
  5. 💻 In the Windows Security "Save your passkey" box, click Change.
  6. 💻 In the "Choose where to save your passkey" box, click Security key.
  7. 🔑️ When prompted, insert your security key into your computer's USB port.
  8. 🔑️ When prompted, touch your security key.
  9. 💻 In the Windows Security "Save your passkey" box, enter your Security Key PIN, then click OK.
  10. 🔑️ When prompted, touch your security key again.
  11. 💻 In the "Let's name your passkey" box, enter a memorable name for your passkey, then click Next.
  12. 💻 In the "Passkey created" box, click Done.

You have successfully added a security key as a passkey MFA sign-in method for your UMS account. If this is the only sign-in method on your account, we recommend adding a second one on a different device before you finish. See the other articles in the How-To Guides collection for additional methods.


Video walkthrough

Use the interactive walkthrough below to follow along step by step.


Common problems

If you run into an issue not covered here, see the MFA Troubleshooting knowledge base articles.

The IT Service Desk is available by phone, email, chat, and walk-up if additional support is needed.

Environment

  • Applies to all University of Maine System (UMS) accounts
  • Requires a FIDO2 hardware security key (such as a YubiKey) with a PIN already configured
  • Requires a web browser on a computer to complete setup
  • Steps shown are for Windows 11; options may differ on macOS, Linux, or Windows 10